CVE-2014-3004

Castor < 1.3.3 - XML External Entity Injection via Default Xerces SAX Parser Configuration

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-3004. PoCs published by Ron Gutierrez.

AI-analyzed exploit summary This exploit demonstrates an XXE (XML External Entity) vulnerability in the Castor Library, allowing an attacker to read arbitrary files from the server. The PoC shows how malicious XML input can be used to disclose sensitive information like /etc/passwd.

Description

The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Ron Gutierrez · textremotemultiple
https://www.exploit-db.com/exploits/39205

This exploit demonstrates an XXE (XML External Entity) vulnerability in the Castor Library, allowing an attacker to read arbitrary files from the server. The PoC shows how malicious XML input can be used to disclose sensitive information like /etc/passwd.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Castor Library 1.3.3-RC1 and earlier
No auth needed
Prerequisites: User-controlled XML input to the application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2014-06/msg00043.html
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/May/142
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59427
Broken Link vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/67676

Scores

EPSS 0.0363
EPSS Percentile 88.1%

Details

CWE
CWE-611
Status published
Products (8)
castor/castor 0Maven
castor_project/castor 1.3
castor_project/castor 1.3.1
castor_project/castor < 1.3.2
opensuse/opensuse 13.1
opensuse_project/opensuse 12.3
org.castor/castor 0Maven
org.codehaus.castor/castor 0 - 1.3.3Maven
Published Jun 11, 2014
Tracked Since Feb 18, 2026